Security and compliance

Group cards hold kind words, photos and sometimes money, so we treat them with care. This page lists the controls in place today, and is honest about what is still on the way.

SOC 2 Type II: where we are

Thankeeu has not been audited for SOC 2 yet. Our controls are designed around the SOC 2 Trust Services Criteria for security, availability and confidentiality, and an independent SOC 2 Type II audit is planned. Until a report exists we will not claim certification. Enterprise customers can request our completed security questionnaire and a data processing agreement.

Identity and access

Single sign-on (Enterprise)

SAML 2.0 and OpenID Connect with Okta, Microsoft Entra ID, Google Workspace, OneLogin, JumpCloud and other identity providers.

Verified domains

Only email addresses on domains a company has proven it owns, with a DNS record, can sign in with single sign-on.

Single sign-on required

Enterprise admins can require single sign-on for every member, after a successful test so nobody is locked out.

Roles and permissions

HR owners, core team members with full, medium or limited access, and team members each see only what their role allows.

Session timeout

Company and member dashboards sign out after 30 minutes without activity.

Protecting data

Encryption in transit

Every connection uses HTTPS (TLS), with HTTP Strict Transport Security.

Encryption at rest

Our database is hosted on Supabase, which encrypts data at rest (AES-256). Identity provider secrets are additionally encrypted by Thankeeu with AES-256-GCM.

Passwords

Stored only as salted hashes (Argon2id or bcrypt), never in plain text.

Payments

Card payments are handled on our payment providers’ hosted checkouts. Thankeeu never sees or stores card numbers.

Monitoring and accountability

Activity log

Sign ins, single sign-on changes, approvals and other admin actions are recorded in each company’s activity log.

Break-glass access

When single sign-on is required, the HR owner can still sign in with a password if the identity provider is down, and every such sign in is logged.

Abuse protection

Sign-in and sensitive endpoints are rate limited to slow down password guessing and automated abuse.

Your data, your control

Export

Ask us for a copy of your company’s data and we will send it to you.

Deletion

Ask us to delete a company workspace or personal data and we will confirm when it is done.

Data processing agreement

Available to companies on request.

Security questions: hello@thankeeu.com